CVE List

Id CVE No. Status Description Phase Votes Comments Actions
121  CVE-1999-0121  Candidate  Buffer overflow in dtaction command gives root access.  Proposed (19990617)  ACCEPT(2) Dik, Northcutt | MODIFY(3) Baker, Frech, Prosser | REVIEWING(1) Christey  Frech> Reference: XF:dtaction-bo | Reference: XF:sun-dtaction | Prosser> Buffer overflow also affects /usr/dt/bin/dtaction in libDtSvc.a | library in AIX 4.x, but reference for this Sun vulnerability should | only reflect the Sun Bulletin or the CIAC I-032 version of the Sun | Bulletin | Christey> This is the Same Codebase as CVE-1999-0089, so the two entries | should be merged. | Frech> Replace sun-dtaction(732) with dtaction-bo(879) | Baker> Merge with 1999-0089  View
3886  CVE-2001-1082  Candidate  Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.  Proposed (20020131)  ACCEPT(4) Armstrong, Baker, Cole, Green | MODIFY(1) Christey | NOOP(2) Foat, Wall | REJECT(1) Frech  Frech> Reference no longer exists, and has no title for cross | reference. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Frech> Dead reference; will reconsider revote if valid reference | presented. | Christey> MISC:http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0009.html  View
525  CVE-1999-0528  Candidate  A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.  Proposed (19990726)  ACCEPT(3) Baker, Meunier, Northcutt | MODIFY(1) Frech  Frech> possibly XF:nisd-dns-fwd-check | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:firewall-external-packet-forwarding(8372)  View
611  CVE-1999-0629  Candidate  The ident/identd service is running.  Proposed (19990721)  ACCEPT(2) Baker, Ozancin | MODIFY(1) Frech | NOOP(2) Christey, Wall | REJECT(1) Northcutt  Frech> possibly XF:identd? | Christey> XF:ident-users(318) ? | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:identd-vuln(61) | XF:ident-users(318)  View
193  CVE-1999-0193  Candidate  Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.  Proposed (19990714)  ACCEPT(5) Bishop, Cole, Northcutt, Ozancin, Shostack | MODIFY(2) Baker, Blake | NOOP(4) Armstrong, Frech, Landfield, Wall | REVIEWING(2) Christey, Levy  Frech> possibly XF:ascend-kill | I can"t find a reference that lists both routers in the same reference. | Wall> Comment: There is a reference about the zero length TCP option in BugTraq on | Feb 5, 1999 | and it mentions Cisco, but not directly Ascend or 3Com. CIAC Advisory I-038 | mentions | vulnerabilities in Ascend, but does not mention TCP. CIAC Advisory I-052 | mentions | 3Com vulnerabilities, but not TCP. Too confusing withour better references. | Landfield> What are the references for this ? I cannot find a means to check it out. | CHANGE> [Frech changed vote from REVIEWING to NOOP] | Frech> Cannot reconcile to our database without further references. | Blake> I"m with Andre. I only remember and can find reference to the Ascend | issue. Do we have a refernce to the 3Coms? If not, that should be | removed from the description. | Baker> http://xforce.iss.net/static/614.php Misc Defensive Info | http://www.securityfocus.com/archive/1/5682 Misc Offensive Info | http://www.securityfocus.com/archive/1/5647 Misc Defensive Info | http://www.securityfocus.com/archive/1/5640 Misc Defensive Info | CHANGE> [Armstrong changed vote from REVIEWING to NOOP]  View

Page 224 of 20943, showing 5 records out of 104715 total, starting on record 1116, ending on 1120

Actions